
TOP All bugbounty pentesting CVE-2023- POC Exp RCE example payload Things
all Top Top Top_Codeql TOP All bugbounty pentesting CVE-2022- POC Exp Things
| star | updated_at | name | url | des |
|---|---|---|---|---|
| 4074 | 2026-10-08T04:08:46Z | copy-fail-CVE-2026-31431 | https://github.com/theori-io/copy-fail-CVE-2026-31431 | Copy Fail (CVE-2026-31431): 9-year-old Linux kernel LPE found by Theori's Xint Code |
| 788 | 2026-10-08T21:55:27Z | wp2shell-poc | https://github.com/Icex0/wp2shell-poc | wp2shell (CVE-2026-63030 & CVE-2026-60137) - full RCE chain |
| 1687 | 2026-10-09T03:34:31Z | ghostlock-app | https://github.com/YuKongA/ghostlock-app | GhostLock One-Tap Execution App (CVE-2026-43499) |
| 183 | 2026-10-06T14:06:06Z | next-16.2.4-pocs | https://github.com/dwisiswant0/next-16.2.4-pocs | Next.js v16.2.4 Security PoC Collection (CVE-2026-23870, CVE-2026-44575, CVE-2026-44579, CVE-2026-44574, CVE-2026-44578, CVE-2026-44573, CVE-2026-44581, CVE-2026-44580, CVE-2026-44577, CVE-2026-44576, CVE-2026-44582, CVE-2026-44572) |
| 967 | 2026-10-08T21:46:52Z | BYOVD | https://github.com/BlackSnufkin/BYOVD | BYOVD research use cases featuring vulnerable driver discovery and reverse engineering methodology. (CVE-2025-52915, CVE-2025-1055, CVE-2026-3609, CVE-2026-8501). |
| 577 | 2026-10-03T09:42:22Z | cve_2026_31431 | https://github.com/rootsecdev/cve_2026_31431 | Exploit POC for CVE_2026_31431 |
| 143 | 2026-10-09T00:28:44Z | wp2shell | https://github.com/manpisetsu/wp2shell | CVE-2026-63030 + CVE-2026-60137 exploit RCE chain |
| 332 | 2026-10-03T05:49:02Z | CVE-2026-54121 | https://github.com/aniqfakhrul/CVE-2026-54121 | Certighost POC |
| 251 | 2026-10-08T07:03:13Z | CVE-2026-43499-popsicle | https://github.com/x-spy/CVE-2026-43499-popsicle | CVE-2026-43499 Implementation for 6.12.23-android16-5-g75e9b1c7ae7c-abogki463945075-4k |
| 1378 | 2026-10-09T00:45:34Z | Root-My-Galaxy | https://github.com/BuSung-dev/Root-My-Galaxy | KSU installer for supported Samsung Galaxy firmware with CVE-2026-43499 |
| 231 | 2026-09-20T20:12:00Z | CVE-2026-41089 | https://github.com/0xABCD01/CVE-2026-41089 | Netlogon and CLDAP vulnerability research with a proof of concept. |
| 303 | 2026-09-28T08:18:46Z | CVE-2026-21858 | https://github.com/Chocapikk/CVE-2026-21858 | n8n Ni8mare - Unauthenticated Arbitrary File Read to RCE Chain (CVSS 10.0) |
| 261 | 2026-09-28T02:20:04Z | CVE-2026-40369-EXPLOIT | https://github.com/orinimron123/CVE-2026-40369-EXPLOIT | Full exploit code for CVE-2026-40369 - A Windows kernel arbitrary write vulnerability that allows browser sandbox escape from all browsers render process sandbox |
| 208 | 2026-09-11T02:48:30Z | CVE-2026-24061 | https://github.com/SafeBreach-Labs/CVE-2026-24061 | Exploitation of CVE-2026-24061 |
| 160 | 2026-09-26T04:26:40Z | CVE-2026-43499 | https://github.com/MobiusM/CVE-2026-43499 | CVE-2026-43499 PoC |
| 360 | 2026-10-03T14:18:05Z | copyfail-go | https://github.com/badsectorlabs/copyfail-go | A Go implementation of copyfail (CVE-2026-31431) |
| 115 | 2026-10-06T05:54:08Z | wp2shell | https://github.com/0xsha/wp2shell | CVE-2026-63030 + CVE-2026-60137 - “wp2shell”: unauthenticated RCE in WordPress core |
| 184 | 2026-10-06T20:41:18Z | CVE-2026-62911 | https://github.com/hypnguyen1209/CVE-2026-62911 | POC pre-auth RCE on Exchange |
| 142 | 2026-10-04T13:17:45Z | CVE-2026-42980-POC | https://github.com/G4sp4rCS/CVE-2026-42980-POC | CVE-2026-42980 PUBLIC EXPLOIT + RESEARCH |
| 450 | 2026-10-08T18:44:32Z | LSPromise | https://github.com/LSPosed/LSPromise | Android complete exploit chain that enables privilege escalation from a local untrusted app to root/kernel, combination of CVE-2026-49881 and CVE-2026-43284 |
| 508 | 2026-10-07T22:57:52Z | cPanelSniper | https://github.com/ynsmroztas/cPanelSniper | CVE-2026-41940 — cPanel & WHM Authentication Bypass via Session-File CRLF Injection |
| 429 | 2026-10-09T01:58:41Z | Root-My-Pixel | https://github.com/alex193a/Root-My-Pixel | Jailbreak supported Google Pixel phones with CVE-2026-43499 |
| 105 | 2026-10-08T14:54:33Z | CVE-2026-75604-poc | https://github.com/rafabd1/CVE-2026-75604-poc | CVE-2026-75604 Next.js Windows RCE poc |
| 54 | 2026-09-27T21:53:28Z | samsung-android-lpe | https://github.com/Vikramaditya015/samsung-android-lpe | Poc for CVE-2026-20980, CVE-2026-20981, CVE-2026-20982 |
| 221 | 2026-10-02T18:27:29Z | ResetNightmare | https://github.com/Semperis-Community/ResetNightmare | POC tool for ResetNightmare (CVE-2026-27912) |
| 66 | 2026-09-23T13:49:05Z | wp2shell-scanner | https://github.com/ZephrFish/wp2shell-scanner | CVE-2026-63030, CVE-2026-60137, wp2shell scanner |
| 129 | 2026-09-24T18:06:13Z | CVE-2026-20817 | https://github.com/oxfemale/CVE-2026-20817 | Windows Error Reporting ALPC Elevation of Privilege (CVE-2026-20817) - Proof-of-Concept exploit demonstrating local privilege escalation via WER service. |
| 400 | 2026-10-08T10:58:36Z | ghostlock-oneplus | https://github.com/JoinChang/ghostlock-oneplus | GhostLock (CVE-2026-43499) kernel exploit for Android devices with locked bootloader |
| 125 | 2026-10-06T04:08:14Z | CVE-2026-41651 | https://github.com/Vozec/CVE-2026-41651 | |
| 108 | 2026-10-08T16:52:52Z | CVE-2026-43499-Poc-Analysis | https://github.com/Linuxoid-cn/CVE-2026-43499-Poc-Analysis | Vulnerability analysis and Proof of Concept (PoC) for CVE-2026-43499 affecting Xiaomi devices. For educational and research purposes only. |
| star | updated_at | name | url | des |
|---|---|---|---|---|
| 2454 | 2026-10-08T02:42:40Z | react2shell-scanner | https://github.com/assetnote/react2shell-scanner | High Fidelity Detection Mechanism for RSC/Next.js RCE (CVE-2025-55182 & CVE-2025-66478) |
| 1431 | 2026-10-08T19:53:54Z | CVE-2025-55182 | https://github.com/msanft/CVE-2025-55182 | Explanation and full RCE PoC for CVE-2025-55182 |
| 792 | 2026-09-17T03:00:41Z | CVE-2025-55182-research | https://github.com/ejpir/CVE-2025-55182-research | CVE-2025-55182 POC |
| 493 | 2026-08-11T09:12:24Z | CVE-2018-20250 | https://github.com/WyAtu/CVE-2018-20250 | exp for https://research.checkpoint.com/extracting-code-execution-from-winrar |
| 719 | 2026-10-03T01:45:49Z | CVE-2025-33073 | https://github.com/mverschu/CVE-2025-33073 | PoC Exploit for the NTLM reflection SMB flaw. |
| 967 | 2026-10-08T21:46:52Z | BYOVD | https://github.com/BlackSnufkin/BYOVD | BYOVD research use cases featuring vulnerable driver discovery and reverse engineering methodology. (CVE-2025-52915, CVE-2025-1055, CVE-2026-3609, CVE-2026-8501). |
| 529 | 2026-10-08T15:56:49Z | CVE-2025-32463_chwoot | https://github.com/pr0v3rbs/CVE-2025-32463_chwoot | Escalation of Privilege to the root through sudo binary with chroot option. CVE-2025-32463 |
| 247 | 2026-10-03T01:45:59Z | IngressNightmare-PoC | https://github.com/hakaioffsec/IngressNightmare-PoC | This is a PoC code to exploit the IngressNightmare vulnerabilities (CVE-2025-1097, CVE-2025-1098, CVE-2025-24514, and CVE-2025-1974). |
| 345 | 2026-10-05T10:58:12Z | redis_exploit | https://github.com/raminfp/redis_exploit | CVE-2025-49844 (RediShell) |
| 476 | 2026-10-08T13:24:55Z | CVE-2025-32463 | https://github.com/kh4sh3i/CVE-2025-32463 | Local Privilege Escalation to Root via Sudo chroot in Linux |
| 266 | 2026-10-03T01:45:57Z | CVE-2025-48799 | https://github.com/Wh04m1001/CVE-2025-48799 |